The Attacker’s New Shortcut: Device Code Phishing
According to a recent report shared with The Hacker News, a commercial phishing toolkit called Greatness has added a dangerous new feature. It now supports device code phishing, a technique that abuses a legitimate login process to bypass multi-factor authentication (MFA). This is significant because MFA has long been the gold standard for protecting business accounts.
The method works by tricking users into entering a short code on a real Microsoft login page. Because the page is genuine, the victim sees nothing obviously wrong. The attacker, meanwhile, captures the session token, which works like a digital key. Once they have that token, they can access accounts without needing a password or a second factor at all.
Why This Changes the Game for Cybersecurity
MFA was supposed to stop exactly this kind of theft. But device code phishing shows that attackers are evolving faster than many defences. They are not breaking the security system—they are exploiting how normal login flows work. For Australian businesses, this is a wake-up call that no single tool can guarantee safety.
The Greatness platform is sold as a subscription service, making advanced cyber threats available to criminals with little technical skill. This is part of a broader trend where cybercrime operates like a business. Tools that once required expert knowledge are now rented out cheaply, lowering the barrier for anyone who wants to launch an attack.
What This Means for Australian SMBs
Small and mid-sized businesses in Australia often rely on services like Microsoft 365 and Google Workspace. These services are exactly what Greatness targets. Because SMBs typically have fewer IT staff, they may not spot a phishing email that looks like a voicemail notification or a document share request.
Even if your team has MFA enabled, it can be bypassed through device code phishing. The attacker does not need to steal your password—they just need a few seconds of your attention. For an Australian SMB, a compromised account can lead to stolen customer data, financial loss, and damage to your reputation that takes years to rebuild.
What You Can Do Now
- Train your staff to be suspicious of any unexpected message that asks them to enter a short code on a login page, even if the page looks familiar.
- Review your email security settings to limit the use of "safe sender" lists, which attackers exploit to bypass spam filters.
- Enable conditional access policies that block sign-ins from unfamiliar locations or devices, adding a layer of protection beyond standard MFA.
- Conduct regular security checks on all third-party apps connected to your accounts, since stolen tokens can be reused to access other services.
- Create a clear incident response plan so your team knows exactly what to do if a suspicious login attempt is reported.
These steps can help you stay ahead of evolving threats, and MS&VG regularly helps Australian SMBs build practical defences that fit their budget and team size.